PT-2020-9708 · Mantisbt · Mantisbt
Roland Becker
·
Published
2020-03-19
·
Updated
2022-05-24
·
CVE-2019-15539
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MantisBT versions prior to 2.21.3
Description
The issue affects the Project Documentation feature, specifically the proj doc edit page.php file, allowing for a stored cross-site scripting (XSS) attack. This occurs when an attachment with a specially crafted filename is uploaded. The arbitrary code is executed when the document's page is edited, provided the Content Security Policy (CSP) settings permit it.
Recommendations
For versions prior to 2.21.3, update to version 2.21.3 or later to resolve the issue. As a temporary workaround, consider restricting the upload of attachments to trusted users only, and avoid editing documents that may contain malicious filenames until the update is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mantisbt